paper-with-me

홈 › Papers

LLMPot: Dynamically Configured LLM-based Honeypot for Industrial Protocol and Physical Process Emulation

2024-05-09 · Christoforos Vasilatos, Dunia J. Mahboobeh, Hithem Lamri, Manaar Alam, Michail Maniatakos

Industrial Control Systems (ICS) are extensively used in critical infrastructures ensuring efficient, reliable, and continuous operations. However, their increasing connectivity and addition of advanced features make them vulnerable to cyber threats, potentially leading to severe disruptions in essential services. In this context, honeypots play a vital role by acting as decoy targets within ICS networks, or on the Internet, helping to detect, log, analyze, and develop mitigations for ICS-specific cyber threats. Deploying ICS honeypots, however, is challenging due to the necessity of accurately replicating industrial protocols and device characteristics, a crucial requirement for effectively mimicking the unique operational behavior of different industrial systems. Moreover, this challenge is compounded by the significant manual effort required in also mimicking the control logic the PLC would execute, in order to capture attacker traffic aiming to disrupt critical infrastructure operations. In this paper, we propose LLMPot, a novel approach for designing honeypots in ICS networks harnessing the potency of Large Language Models (LLMs). LLMPot aims to automate and optimize the creation of realistic honeypots with vendor-agnostic configurations, and for any control logic, aiming to eliminate the manual effort and specialized knowledge traditionally required in this domain. We conducted extensive experiments focusing on a wide array of parameters, demonstrating that our LLM-based approach can effectively create honeypot devices implementing different industrial protocols and diverse control logic.

📄 PDF Abstract BibTeX arXiv:2405.05999

Code (1)

momalab/llmpot 공식 구현

Similar Papers 제목 키워드 기반

A Generative Model Based Honeypot for Industrial OPC UA Communication

2024-10-28 · Olaf Sassnick, Georg Schäfer, Thomas Rosenstatter, Stefan Huber

Industrial Operational Technology (OT) systems are increasingly targeted by cyber-attacks due to their integration with Information Technology (IT) systems in the Industry 4.0 era. Besides intrusion detection systems, ho…

Intrusion Detection

Measuring and Clustering Network Attackers using Medium-Interaction Honeypots

2022-06-27 · Zain Shamsi, Daniel Zhang, Daehyun Kyoung, Alex Liu

Network honeypots are often used by information security teams to measure the threat landscape in order to secure their networks. With the advancement of honeypot development, today's medium-interaction honeypots provide…

Clustering

ICSTrace: A Malicious IP Traceback Model for Attacking Data of Industrial Control System

2019-12-30 · Feng Xiao, Qiang Xu

Considering the attacks against industrial control system are mostly organized and premeditated actions, IP traceback is significant for the security of industrial control system. Based on the infrastructure of the Inter…

Clustering

Security Orchestration, Automation, and Response Engine for Deployment of Behavioural Honeypots

2022-01-14 · Upendra Bartwal, Subhasis Mukhopadhyay, Rohit Negi, Sandeep Shukla

Cyber Security is a critical topic for organizations with IT/OT networks as they are always susceptible to attack, whether insider or outsider. Since the cyber landscape is an ever-evolving scenario, one must keep upgrad…

Intrusion DetectionManagement

Honeypot Protocol

2026-04-14 · Najmul Hasan arxiv

Trusted monitoring, the standard defense in AI control, is vulnerable to adaptive attacks, collusion, and strategic attack selection. All of these exploit the fact that monitoring is passive: it observes model behavior b…